OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Andrew Kopp (drewk_at_nexed.net)
Date: Tue Dec 17 2002 - 23:18:43 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    I don't really think this falls into vulnerability because most software
    will prompt you before it overwrites any file by default. And if anyone
    would actually allow their own SSHd binary to be over written deserves
    to be hacked.

    And to those who extract an un-trusted archive and set the "don't prompt
    me" flag, you really need a lesson in 'basic' (very obvious too!)
    security practices.

    No pun intended.

    Regards,

    drewk~

    -----Original Message-----
    From: Florian Schafferhans [mailto:fscomputer-security.de]
    Sent: Monday, December 16, 2002 6:41 PM
    To: bugtraqsecurityfocus.com
    Subject: Directory traversal vulnerabilities in several archivers
    processing .tar

    Subject

      Directory traversal vulnerabilities in several
    archivers processing .tar
     files

    [ email... blah blah blah blah ]